---
schema_version: '1.0'
id: news-20260721-85c7c3
url: https://gotosocial.chinng-lab-srv.dev/mi-jin-rong-da-shou-capital-onegaaisekiyuriteituru-vulnhunter-woossgong-kai-gong-ji-zhe-shi-dian-noezientojie-xi-gatuo-kudevsecopsnoxin-shi-dai/
url_hash: 85c7c33dbd0255b1965972378d9bd6e82e491ff45e0ea1ef2e7a85c8ce5ab529
canonical_url: https://gotosocial.chinng-lab-srv.dev/mi-jin-rong-da-shou-capital-onegaaisekiyuriteituru-vulnhunter-woossgong-kai-gong-ji-zhe-shi-dian-noezientojie-xi-gatuo-kudevsecopsnoxin-shi-dai
source: ghost-chinng-lab
category: news/tech
category_raw: AI・テクノロジー
region: JP
tags:
- AI・テクノロジー
- Capital One
- VulnHunter
- AIエージェント
- DevSecOps
- サイバーセキュリティ
- オープンソース
lang: ja
published_at: '2026-07-21T03:16:17Z'
fetched_at: '2026-07-21T03:38:30.334670Z'
updated_at: '2026-07-21T03:38:49Z'
status: published
content_hash: null
content_changed_at: null
license_note: full
summary: 米金融大手のCapital Oneが、自律型AIエージェントを活用したセキュリティツール「VulnHunter」をApache 2.0ライセンスでオープンソース公開しました。このツールは従来の静的セキュリティテスト（SAST）の課題である大量の誤検知を解決するため、攻撃者の視点からコードのデータフロー追跡性を検証し、実効的な脆弱性のみを特定します。反証エンジンと独立検証エージェントの二重構造により、修正案の品質も確保。AI時代のセキュアな開発環境（DevSecOps）を実現する技術の提供が狙いです。
summary_source: llm
summary_en: Capital One, a leading U.S. finance company, has released a security tool
  called "VulnHunter" using autonomous AI agent. This toolを解決するs code data flow tracking
  from the attacker’s point of view to solve a large number of false-sensing issues
  with conventional static security testing (SAST), and only identifys effective vulnerabilities.
  The double structure of the anti-certification engine and independent verification
  agent ensures the quality of the modification. We aim to provide technology that
  realizes a secure development environment (DevSecOps) in the AI era。
entities:
- name: Capital One
  type: organization
- name: VulnHunter
  type: artifact
- name: AIエージェント
  type: concept
- name: サイバーセキュリティ
  type: concept
- name: オープンソースモデル
  type: method
- name: OnePlus
  type: organization
- name: Rossum
  type: person
key_facts: []
related: []
related_auto:
- name: agent_hermes
  type: person
  weight: 12.0
- name: Vertu
  type: organization
  weight: 4.0
- name: Attacker-First Forward Analysis
  type: method
  weight: 1.0
- name: GitHub
  type: artifact
  weight: 1.0
- name: data_flow
  type: UNKNOWN
  weight: 1.0
title: 米金融大手Capital OneがAIセキュリティツール「VulnHunter」をOSS公開：攻撃者視点のエージェント解析が拓くDevSecOpsの新時代
---

# 米金融大手Capital OneがAIセキュリティツール「VulnHunter」をOSS公開：攻撃者視点のエージェント解析が拓くDevSecOpsの新時代

## TL;DR
米金融大手のCapital Oneが、自律型AIエージェントを活用したセキュリティツール「VulnHunter」をApache 2.0ライセンスでオープンソース公開しました。このツールは従来の静的セキュリティテスト（SAST）の課題である大量の誤検知を解決するため、攻撃者の視点からコードのデータフロー追跡性を検証し、実効的な脆弱性のみを特定します。反証エンジンと独立検証エージェントの二重構造により、修正案の品質も確保。AI時代のセキュアな開発環境（DevSecOps）を実現する技術の提供が狙いです。

## Key Points
- AI・テクノロジー / Capital One / VulnHunter / AIエージェント / DevSecOps / サイバーセキュリティ / オープンソース

## Details
(本文なし。リンク先参照)

## Source
元記事: [米金融大手Capital OneがAIセキュリティツール「VulnHunter」をOSS公開：攻撃者視点のエージェント解析が拓くDevSecOpsの新時代](https://gotosocial.chinng-lab-srv.dev/mi-jin-rong-da-shou-capital-onegaaisekiyuriteituru-vulnhunter-woossgong-kai-gong-ji-zhe-shi-dian-noezientojie-xi-gatuo-kudevsecopsnoxin-shi-dai/) — published 2026-07-21T03:16:17Z
